logo

Database

FISMA

Last updated: 2024/01/12
logo

The Federal Information Security Management Act (FISMA) was originally passed in 2002 as part of the Electronic Government Act. FISMA defines a framework of guidelines and security standards to protect government information and operations. FISMA requires all federal agencies to develop, document and implement agency-wide information security programs. NIST SP 800-53 serves as the primary resource that federal agencies use to implement the security controls required by FISMA. The IDs for these controls correspond to those of the NIST 800-53 standard. The version used for this section is NIST 800-53, Rev. 5, September 2020.

Control-Requirement Mapping

DefinitionRequirements
AC-2_2. Removal of temporary or emergency accounts
AC-2_3. Disable accounts
AC-2_4. Automated audit actions
AC-2_6. Dynamic privilege management
AC-2_7a. Establish and administer privileged user accounts
AC-2_7b. Monitor privileged role or attribute assignments
AC-2_7c. Monitor changes to roles or attributes
AC-2_10. Shared and group account credential change
AC-2_13. Disable accounts for high-risk individuals
AC-6. Least privilege
AC-12. Session termination
AC-18_5. Antennas and transmission power levels
IA-1. Policy and procedures
IA-2. Identification and authentication (organizational users)
IA-7. Cryptographic module authentication
PL-4_1. Social media and external site/applications usage restrictions
SC-3. Security function isolation